摘要
简要介绍了国内外信息安全评估标准的发展过程,指出各应用领域或各组织进行信息安全风险评估的重要性。阐述了信息安全风险评估所要解决的问题,介绍了目前在信息安全风险评估领域的主要方法,并对这些方法进行了分析和评价。
The history of information system security evaluation criteria at home and abroad points out the importance of each application field while carries through with information security risk evaluation. The information security risk evaluation question is elabrated, the major methods in information security risk evaluation fields are introduced, and the methods are analyzed and studied.
出处
《科学技术与工程》
2007年第10期2350-2353,共4页
Science Technology and Engineering
关键词
风险评估
资产
威胁
薄弱点
risk evauation asset threat weak point